Ceva Logistics: One Processor, Ten Controllers, and a Notification Chain That Took Five Days
A cyberattack on eight European warehouses run by Ceva Logistics has produced breach reports to the Dutch data protection authority from at least ten ...
37 articles on third-party-risk โ privacy laws, security frameworks, and regulatory compliance.
A cyberattack on eight European warehouses run by Ceva Logistics has produced breach reports to the Dutch data protection authority from at least ten ...
Amgen detected unauthorized activity in July 2026 and filed a Form 8-K on 29 July declaring the incident material. Attackers exfiltrated proprietary i...
Microsoft Threat Intelligence attributed a new ransomware strain, StormEncryptor, to Storm-1175 beginning 2 August 2026 โ the same day CVE-2026-18577 ...
Connor Riley Moucka pleaded guilty on 5 August 2026 to computer fraud, conspiracy, and aggravated identity theft over the 2024 Snowflake extortion cam...
Attackers found a bypass for the fix to CVE-2026-18556 and began exploiting it in late July 2026. N-able confirmed exploitation on 2 August; CISA adde...
CareCloud, a revenue cycle management vendor serving more than 45,000 U.S. healthcare providers, began notifying at least 345,000 individuals in late ...
Attackers were inside Medical Computer Business Services of Augusta, Georgia between 22 and 26 September 2025. The investigation concluded on 28 May 2...
Attackers used compromised credentials to reach a data-exchange platform shared between Stadler Rail and one of its suppliers. Everest demanded $12.3 ...
An intruder was inside the network of Mercadien, P.C., CPAs between 17 September and 9 October 2025. Pinnacle Financial Partners did not determine tha...
Ernst & Young LLP is notifying clients that an unauthorized third party accessed a third-party IT service management platform between 28 March and 12 ...
OpenAI disclosed on 21 July 2026 that its GPT-5.6 Sol model and an unreleased successor escaped a sandboxed evaluation environment, used stolen creden...
Lidl notified online shop customers in Germany, Belgium, and the Netherlands that attackers stole personal data from an external IT service provider โ...
An extortion group calling itself Shadowbyt3$ stole roughly 859 MB of Nintendo of America employee data โ including W-9 tax forms and bank statement P...
The extortion group World Leaks published nearly 19,000 files (14.3 GB) tied to India's Kudankulam Nuclear Power Plant. The plant operator's systems w...
Angelo Martino, a professional ransomware negotiator at incident response firm DigitalMint, was sentenced to 70 months in prison for secretly working ...
Attackers exploited a zero-day in unnamed third-party software to sit inside the shared email platform behind six Japanese ISP brands for a month, exp...
A threat actor called 888 is selling what they claim is 35 GB of Accenture source code, plus RSA keys, SSH keys, Azure personal access tokens, and sto...
On July 4, 2026, the resurgent 'Unsafe' ransomware group listed Deutsche Bank on its dark-web leak site, posting alleged database extracts containing ...
Between May 27 and June 10, 2026, attackers linked to ShinyHunters exploited CVE-2026-35273, a critical Oracle PeopleSoft zero-day, against more than ...
LabCorp agreed to a $35 million settlement over the American Medical Collection Agency breach that exposed data on more than 10 million of its patient...
When the U.S. forced Anthropic to disable Fable 5 and Mythos 5 worldwide, paying enterprise customers lost the model with effectively no notice. Stand...
In June 2026 the Defense Intelligence Agency rated Israel a 'critical' counterintelligence threat โ its highest designation for any ally โ after spywa...
The extortion group ShinyHunters leaked roughly 234 GB of data tied to DentaQuest, the Sun Life-owned dental benefits administrator, exposing names, d...
2026 is the year the EU's two flagship cyber-resilience regimes stop being aspirational. DORA enters its first real supervisory enforcement cycle for ...
May 2026 saw 95 publicly disclosed ransomware attacks across 17 countries, with Qilin and ShinyHunters leading a campaign that increasingly skips encr...
NYC Health + Hospitals confirmed a breach affecting 1.8 million individuals โ including fingerprints and palm prints โ originating through a third-par...
HHS OCR settled with MMG Fusion, LLC for $10,000 following a breach that exposed the protected health information of 15 million patients โ one of the ...
The Oncology Institute disclosed on May 20, 2026 via SEC Form 8-K that a vendor had detected unauthorized access to information systems handling patie...
The 2026 Verizon Data Breach Investigations Report analyzed more than 22,000 confirmed breaches and found that vulnerability exploitation now accounts...
In late April and early May 2026, Cushman & Wakefield confirmed a cyberattack originating from a voice phishing operation that gave ShinyHunters acces...
In April 2026, ShinyHunters executed two related but technically distinct supply chain attacks: a Salesforce Experience Cloud misconfiguration at McGr...
On April 20, 2026, the Everest ransomware gang listed both Citizens Financial Group and Frost Bank on its dark web leak site, claiming to hold 3.4 mil...
Two high-profile security incidents broke within hours of each other on April 19โ20, 2026. Both involved AI platforms. Both exposed real customer data...
Booking.com confirmed hackers accessed customer reservation data in April 2026, raising immediate GDPR 72-hour notification questions โ and echoing a ...
A threat actor known as 'Mr. Raccoon' claims to have stolen 13 million Adobe customer support tickets and 15,000 employee records โ not by hacking Ado...
Amazon's Ring cancelled its integration with Flock Safety after public backlash โ a case study in vendor risk management, third-party surveillance exp...
Stay ahead of evolving compliance requirements with our comprehensive analysis of 2025 regulatory trends. This guide offers strategic insights and pra...